Scenario 04 · Espionage · menuPass / Stone Panda / APT10
menuPass builds its foothold quietly — a new local account that answers to no one, a service that starts itself at boot, an admin share mapped for the next hop. We ran that persistence-and-lateral-prep tradecraft end to end on a live Windows victim to exercise techniques our earlier scenarios never touched. THRONE flagged all six actions, mapped each to ATT&CK, and ONYX folded them into a single incident — with no analyst in the loop until there was one thread worth reading.
menuPass — also tracked as Stone Panda and APT10 — is one of China's longest-running espionage crews, best known for hollowing out managed service providers and island-hopping into their customers. Its edge is not noise; it is patience and native Windows tooling. We emulated the persistence-and-lateral-prep core of that tradecraft and watched THRONE catch every step.
On a single Windows host we executed six of the group's signature living-off-the-land actions: enumerate the session's privileges, stand up a new local account, promote it into the local Administrators group, install a self-starting service, map a remote SMB admin share to stage the next hop, and decode a base64 payload through a trusted Microsoft binary. Each is designed to look like ordinary administration. Taken together they are a privileged backdoor, a reboot-proof persistence mechanism and a lateral-movement beachhead.
THRONE fired six detections — three HIGH, two MED, one LOW — each mapped to a distinct ATT&CK technique. Five of the six were detection types this campaign had never triggered before, which was the whole point of the run: surface the persistence and lateral-prep signals the earlier scenarios never produced. ONYX then triaged the burst automatically and collapsed it into one credential-access / persistence incident, INC-55843, rather than leaving six disconnected alerts for an analyst to reassemble by hand.
A China-nexus espionage group tracked by MITRE ATT&CK as G0045 and active since at least 2009. Its defining campaign redefined supply-chain intrusion; its tradecraft is a masterclass in looking like a system administrator.
menuPass — variously called Stone Panda, Red Apollo, POTASSIUM, Cicada and Bronze Riverside — is widely assessed to operate in support of Chinese state intelligence requirements. In December 2018 the US Department of Justice indicted two members of the group, alleging they acted in association with the Chinese Ministry of State Security's Tianjin State Security Bureau. The group's remit is classic strategic espionage: aerospace, defense, government, engineering, telecommunications, biotech, healthcare and the managed-service-provider ecosystem that stitches those sectors together. The objective is intellectual property and long-term access, not disruption.
APT10's signature operation, publicly detailed in 2017, targeted managed IT service providers rather than their ultimate victims directly. By compromising an MSP, the group inherited that provider's trusted, privileged connectivity into dozens of downstream customer networks — then island-hopped from one to the next. In ATT&CK terms this is T1199 (Trusted Relationship): abuse the supplier to reach the customer. It is the strategic reason this scenario matters — the lateral-prep moves we emulated are exactly how a foothold on one managed host becomes a foothold on the next.
APT10 favours stealth and long dwell time. Initial access typically arrives as a spearphishing attachment
(T1566.001). A hallmark of the group is DLL side-loading
(T1574.002) — dropping a legitimately signed executable next to a malicious DLL so a
trusted process loads the attacker's code. From there the group leans heavily on living-off-the-land: the
native net, wmic, sc and PowerShell utilities, scheduled tasks and services
for persistence, and signed system binaries such as certutil for staging and decoding. Its malware
family tree includes the shared RAT PlugX, plus RedLeaves, ChChes, QuasarRAT,
SodaMaster and the Ecipekac/ANEL loader chains. Credential theft, archived-and-encrypted staging,
and exfiltration over HTTPS round out the pattern.
The moves in this scenario are not exotic malware — they are the quiet administrative actions APT10 uses to turn one compromised host into durable, privileged, lateral access. A backdoor local admin survives credential resets; a service survives reboots; an admin-share mount is the on-ramp to the next machine; and certutil decoding lets a next-stage payload arrive as harmless-looking text. Detecting them is detecting APT10's actual working style, not a lab artefact.
No autonomous command-and-control, no embellishment: this was a direct, hand-executed run of menuPass's persistence-and-lateral-prep tradecraft on one instrumented Windows host, cleaned back to baseline afterwards. What we are measuring is the telemetry each action threw and whether THRONE caught it.
Everything ran on a single lab host, WIN-J50RP1JBGD4 (external 204.168.192.149 · internal 10.0.0.5), running Microsoft Sysmon with process-creation, network-connection and file-create logging. We chose direct execution on purpose: the objective was to exercise persistence and lateral-movement techniques the earlier campaign scenarios never produced — not to demonstrate autonomous planning. This is a lab environment, so the real hostname and IP addresses are shown exactly as captured; nothing is redacted.
The host was fully restored after the run. The backdoor local account was deleted, the persistence service was stopped and removed, the scheduled task was unregistered, and the decoded payload artefact was cleared — the box was returned to its pre-run baseline.
Each action on the victim produced a Sysmon event — predominantly Event ID 1 (process creation), carrying the
full command line, the parent process, file hashes and, critically, the ProcessGuid and
ParentProcessGuid that later let THRONE rebuild causality. Those events are forwarded as
tenant-tagged syslog to THRONE's ingest and travel the full pipeline in seconds:
The ch_pump parser normalises each raw event and lands it in ClickHouse, where the Sigma sweep evaluates it against 3,148 detection rules spanning 389 ATT&CK techniques, alongside a behavioral engine that scores sequences rather than single events. Any match becomes an alert; ONYX then triages and groups the alerts into an incident. The tenant tag is what keeps this run isolated to its own cloud tenant end to end — every event, alert and the resulting incident stay scoped to the one tenant throughout.
Each action below is a real menuPass behaviour, mapped to its ATT&CK technique, with what the command actually does and why this adversary reaches for it. THRONE detected every one.
whoami /priv lists the security privileges held by the current access token — entries such as
SeDebugPrivilege, SeBackupPrivilege or SeImpersonatePrivilege. Before an
intruder tries to persist or pivot, they want to know what the current context can already do. APT10 operators
favour this kind of quiet, native reconnaissance because it touches no new binaries and generates no network
traffic — it simply reads state. The answer tells them whether they can skip privilege escalation entirely.
net user <name> <password> /add creates a new local user. For menuPass this is a backdoor
that outlives the initial foothold: it survives a reboot, it survives the owner changing a compromised domain
password, and it blends in with the dozens of service and admin accounts a real Windows host accumulates over its
life. A new account is cheap to create and expensive to notice.
net localgroup Administrators <name> /add adds the new account to the local Administrators
group. A backdoor is only useful if it is privileged. This single command converts a throwaway user into a local
admin that can install software, read any file, manipulate services and authenticate to admin shares on other
hosts — the hinge between persistence and lateral movement.
Installing a Windows service (via sc create and the service control manager) gives the adversary
code that runs automatically, typically with SYSTEM-level rights, every time the machine boots — no user login
required. Services are a classic APT10 persistence mechanism precisely because they are legitimate and ubiquitous;
a single rogue service hides comfortably among the hundreds a Windows host already runs.
net use \\<host>\admin$ authenticates to the hidden administrative share on a remote machine
over SMB (TCP 445). This is the on-ramp to the next host: once an admin share is mapped, the attacker can stage a
payload, copy a service binary, or execute remotely. For a group whose entire reputation is island-hopping from
MSP to customer, admin-share access is the move that turns one compromised box into two.
certutil -decode takes a base64- or hex-encoded file and writes out its decoded contents. certutil is
a Microsoft-signed, always-present certificate utility, which is exactly why it is abused: a next-stage payload
can travel and sit on disk as innocuous-looking text, then be reconstituted by a trusted system binary rather than
a flagged downloader. It is living-off-the-land defense evasion in a single line.
Six alerts fired as the sequence ran on WIN-J50RP1JBGD4, each mapped to an ATT&CK technique and grouped under INC-55843. Shown exactly as captured:
| Alert | Detection | Sev | ATT&CK |
|---|---|---|---|
| ALR-175448 | Suspicious New Service Creation | HIGH | T1543.003 |
| ALR-175453 | File Decoded From Base64/Hex Via Certutil.EXE | HIGH | T1140 |
| ALR-175451 | Security Privileges Enumeration Via Whoami.EXE | HIGH | T1033 |
| ALR-175452 | New User Created Via Net.EXE | MED | T1136.001 |
| ALR-175449 | User Added to Local Administrators Group | MED | T1098 |
| ALR-175450 | Windows Share Mount Via Net.EXE | LOW | T1021.002 |
Three of the six carried a HIGH severity, and they are worth reading closely — they are where a real menuPass intrusion would be caught before the pivot. The two MED alerts are the backdoor itself, and the LOW is the lateral-prep tell. Here is how ONYX read each of the load-bearing ones.
This Sigma rule keys on service-creation telemetry — a new service registered through the service control
manager, visible both as a Sysmon process-creation event for sc.exe and as the corresponding Windows
service-installed record. It is rated HIGH because a brand-new service is both durable (it survives reboots) and
powerful (it typically runs as SYSTEM). ONYX treated it as a persistence anchor and used it as one of the
load-bearing signals when it assembled INC-55843.
The rule matches certutil invoked with a decode flag (-decode / -decodehex).
Legitimate administrative use of certutil to decode files is rare, so the command line itself is the signal.
Mapped to T1140 (Deobfuscate/Decode Files or Information), it is a strong indicator that a next-stage payload is
being reconstituted on disk — which is why ONYX scored it HIGH and foregrounded it in the incident narrative as
evasion riding alongside the persistence, rather than as an isolated utility run.
This detection fires on whoami executed with the /priv argument. On its own, whoami is
benign; with /priv it is a deliberate check of what the current token can do, and in an attack
sequence it is reconnaissance that precedes escalation or persistence. ONYX read it in context — immediately
before an account was created and promoted — and that ordering is part of why the burst grouped into a single
coherent incident rather than scattering into unrelated noise.
Two MED alerts capture the backdoor itself: a new local user created via Net.EXE
(T1136.001) and that user added to the local Administrators group
(T1098). Individually each is the kind of event a busy admin might generate; back to
back, on a host that just enumerated its own privileges, they are a privileged backdoor being stood up. ONYX's
value here is correlation — it is the pairing, and the company those two alerts keep, that elevates the pair above
their MED baseline.
Five of these fired for the first time in the campaign — the signals the earlier scenarios never generated: account creation (T1136.001), Administrators-group addition (T1098), service installation (T1543.003), SMB admin-share access (T1021.002) and certutil decoding (T1140) — the persistence-and-lateral-prep playbook, all caught.
THRONE does not just list alerts — it reconstructs the chain that produced them. Every Sysmon
process-creation event carries a ProcessGuid for the process and a ParentProcessGuid for
the process that spawned it. Stitching child to parent across the whole burst rebuilds the execution tree exactly
as it ran on the box.
For INC-55843 that tree roots at the interactive session on
WIN-J50RP1JBGD4 and branches out through each Net.EXE,
whoami.exe, sc.exe and certutil.exe invocation — the same six actions the
kill-chain section walks through, now linked by their real parent-to-child GUID relationships rather than guessed
at from timestamps. Where an action also leaves a second trail — the service-install record in the Windows System
log, the account-creation and group-change records in the Security log, the outbound SMB connection on TCP 445 —
those corroborating events hang off the same tree, so the incident reads as one story instead of a pile of
coincidences.
Timestamps tell you what happened near each other; process GUIDs tell you what caused what. The parent-to-child lineage is what lets ONYX assert that the privilege check, the backdoor account, the service and the share mount belong to one actor and one session — and it is what an analyst needs to scope the blast radius without replaying the whole host by hand.
menuPass is difficult precisely because almost nothing it does is malware. Every action in this run is a legitimate Windows administrative capability, used the way a real administrator sometimes uses it. The detection problem is not "is this tool bad" — it is "is this the wrong hands, in the wrong order, on the wrong host."
Three things make that hard in practice. First, volume: accounts are created, services are installed and shares are mapped thousands of times a day across a real estate, so a rule that simply alerts on "a service was created" drowns the analyst. Second, sequence: the danger lives in the ordering — privilege check, then backdoor, then promotion, then persistence, then pivot — not in any single event. Third, stealth and patience: APT10 is content to move one hop at a time over weeks, so the signal is spread thin across time and hosts, and the pieces rarely arrive together where a human will notice them.
The finding from this run is that THRONE caught all six behaviours and, more importantly, ONYX reassembled them into one incident without an analyst connecting the dots. That is the difference that matters against a patient espionage actor: six low-context alerts are easy to dismiss one at a time; one incident that reads "a privileged backdoor was stood up and an admin share was mapped for the next hop" is not.
Four concrete moves that make a menuPass-style persistence-and-pivot sequence expensive to run and easy to catch.
A new local account is noisy; a new local account that is promoted into Administrators within seconds, on a host
that just ran whoami /priv, is not. Correlate T1136.001 and
T1098 — and weight them far higher when they arrive together. That pairing is the backdoor
signature, and it is what ONYX leaned on to group INC-55843.
Legitimate administrative use of certutil -decode is rare enough that it should be alerted on every
time (T1140). The same discipline applies to the other signed binaries APT10 favours — run
down certutil, bitsadmin and mshta usage and baseline who, if anyone, is allowed to use them at all.
Server-to-server admin-share traffic is often routine; a workstation mapping admin$ on a peer
(T1021.002) is a lateral-movement tell. Baseline who legitimately reaches admin shares,
and alert on the exceptions — this is the move that stops island-hopping at the first hop instead of the tenth.
The reason INC-55843 read as one story is that Sysmon captured
ProcessGuid/ParentProcessGuid on every process. Deploy Sysmon (or an equivalent EDR) with
process-creation, network and file-create logging, retain it, and make sure your pipeline preserves the
parent-to-child lineage — it is what turns scattered alerts into a scoped incident.